ZeroHour

CVE-2024-32848

large

Authenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
43%p99
Published
()
Modified
AI analysis

Ivanti Endpoint Manager (EPM) contains an SQL injection flaw (CWE-89) that an authenticated attacker with administrator-level privileges can trigger over the network to execute arbitrary code on the EPM core server. Because it requires high privileges and no user interaction, exploitation would likely involve stolen or compromised admin credentials, potentially chained with other EPM flaws, and grants the attacker full confidentiality, integrity and availability impact on the server. All deployments running versions before 2022 SU6, and 2024-release versions before the September 2024 update, are affected. Ivanti has released fixes (2022 SU6 and the September 2024 update), and the flaw carries an elevated near-term exploitation risk (EPSS 43.4%, 99th percentile), though it is not yet in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade Ivanti EPM core servers to 2022 SU6 or apply the September 2024 update, prioritizing internet-exposed consoles given the high EPSS score. Until patched, restrict access to the EPM web console to trusted networks, audit EPM administrator accounts for weak or default credentials, and review logs for unusual console or database activity.

Affected
Ivanti Endpoint Manager (EPM)All versions before 2022 SU6; for the 2024 release, all versions before the September 2024 update (fixed in 2022 SU6 and the September 2024 update)
Estimated exposure
largeroughly 10,000-50,000 EPM core-server deployments worldwide (managed endpoint count likely in the millions) — EPM is a widely deployed on-premises enterprise endpoint-management platform (Ivanti is a major UEM vendor with tens of thousands of customers across its product lines) and each organization typically runs one or a few core servers,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news